> Markdown version of [/jobs/ext/1917483-cybersecurity-consultant](https://www.wearedevelopers.com/jobs/ext/1917483-cybersecurity-consultant). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Consultant - **Company:** CLARIS CONSULTING INC. - **Location:** Honolulu, HI, United States - **Experience:** Experienced - **Salary:** $80,000.0 - $100,000.0 - **Contract:** Permanent contract - **Skills:** Active Directory, Application Programming Interfaces (APIs), Microsoft Antivirus, Software System Penetration Testing, Bash Shell, Network Analysis, Cyber Security, System Configuration, Linux, Identity and Access Management, IT Management, Python (Programming Language), Network Diagrams, Open Web Application Security, Windows PowerShell, Comptia Pentest+ CE, Security Information and Event Management, Strategies of Testing, Software Vulnerability Management, Web Applications, Wireless Networks, Scripting, Cloud Platform System, Mitre Att&ck, Firewalls (Computer Science), Data Management, CIS Benchmarks, Vulnerability Analysis - **Published:** August 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=db517e541ccd41ce ## About the Role This role is intended for a cybersecurity professional with approximately three to five years of relevant experience and a strong technical foundation. The successful candidate will support multiple cybersecurity engagements and should be comfortable moving between technical assessments, vulnerability and remediation work, penetration testing, security program reviews, and related consulting activities. The role requires someone who can independently complete substantial portions of assigned work while coordinating with senior team members on project scope, testing strategy, operational risk, client priorities, and final deliverables. Current and upcoming work includes penetration testing, adversary-focused tabletop exercises, vulnerability remediation, cybersecurity framework reviews, control validation, vendor security reviews, and broader CISO/vCISO program support. The right person will be technically capable, adaptable, self-motivated, and comfortable managing multiple priorities. They should be able to research unfamiliar technologies, produce clear documentation, raise questions or concerns early, and contribute wherever client needs require support., * Approximately three to five years of professional experience in cybersecurity consulting, security assessments, vulnerability management, penetration testing, security operations, governance, risk, compliance, or a closely related area * Strong technical foundation across networking, operating systems, identity and access management, common enterprise services, and security controls * Hands-on experience in multiple areas of cybersecurity, such as security assessments, vulnerability management, remediation, penetration testing, control validation, incident response, or security program support * Practical experience conducting or supporting authorized penetration tests or offensive security assessments * Ability to review and interpret vulnerabilities, scanner results, logs, system configurations, network diagrams, policies, and other technical evidence * Experience evaluating security findings, determining their practical risk, and developing clear remediation recommendations * Familiarity with common security tools and platforms, such as vulnerability scanners, SIEM solutions, endpoint security tools, firewalls, network analysis tools, or penetration testing tools * Working knowledge of Windows, Linux, Active Directory, and enterprise IT environments * Ability to independently complete substantial portions of assigned projects once objectives, scope, and expectations are established * Ability to research unfamiliar technologies, security issues, frameworks, and client environments * Strong written and verbal communication skills, including the ability to document findings and explain technical issues clearly * Ability to manage multiple projects, competing priorities, and changing client needs in a consulting environment * Strong judgment regarding sensitive information, testing boundaries, operational risk, and escalation * Self-motivated, adaptable, and willing to contribute across both technical and non-technical cybersecurity projects * Must currently reside in Hawaii, be authorized to work in the United States, and be able to travel to client locations within Hawaii for onsite project activities, * Experience supporting multiple types of cybersecurity consulting engagements across technical assessment, remediation, vulnerability management, penetration testing, or security program activities * Experience with internal and external network penetration testing * Experience assessing web applications, APIs, cloud environments, wireless networks, identity systems, or Active Directory * Experience with vulnerability management, remediation validation, security control testing, or technical risk assessments * Experience supporting cybersecurity tabletop, red-team, purple-team, or incident response exercises * Experience with cybersecurity frameworks such as NIST CSF, NIST SP 800-53, CIS Controls, ISO 27001, or similar standards * Experience supporting CISO/vCISO, governance, risk, compliance, or broader security program activities * Experience evaluating third-party security documentation or supporting vendor risk reviews * Experience presenting technical findings and recommendations to clients or organizational leadership * Familiarity with MITRE ATT&CK, PTES, OWASP guidance, or similar testing methodologies * Familiarity with scripting or automation using Python, PowerShell, Bash, or similar languages * Experience with security platforms such as CrowdStrike, Microsoft Defender, SIEM solutions, firewalls, endpoint security tools, or vulnerability management platforms * Relevant certifications such as Security+, CySA+, OSCP, PNPT, GPEN, PenTest+, CISSP, CISA, or similar are preferred but not required * Prior consulting, military, government, financial services, insurance, or other regulated-industry experience is a plus What We're Looking For We are looking for someone who: * Has a strong technical foundation and is willing to work across a broad range of cybersecurity projects * Can evaluate technical issues methodically rather than relying only on automated tools * Produces clear, defensible findings supported by organized evidence * Can explain technical risk accurately and provide practical recommendations * Is comfortable shifting between assessments, remediation, penetration testing, documentation, and advisory support * Can work independently while knowing when to involve senior team members * Raises blockers, operational risks, and testing concerns early * Is comfortable researching unfamiliar environments and developing an appropriate approach * Can balance technical depth with project timelines and business needs * Is interested in helping strengthen Claris Consulting's technical assessment and cybersecurity advisory capabilities, * Cybersecurity: 3 years (Preferred) Ability to Commute: * Honolulu, HI 96816 (Required) Work Location: Hybrid remote in Honolulu, HI 96816 ## Description * Support technical security assessments, control reviews, vulnerability management, and remediation efforts * Review and validate security findings, vulnerabilities, system configurations, and supporting technical evidence * Research vulnerabilities, attack techniques, security controls, and practical remediation options * Track remediation progress and help validate whether identified issues have been effectively resolved * Conduct internal, external, network, web application, and other penetration testing activities within approved rules of engagement * Perform reconnaissance, vulnerability validation, exploitation, privilege escalation, lateral movement, and post-exploitation testing as appropriate * Perform onsite testing, technical validation, and evidence collection at client facilities when required * Identify realistic attack paths and explain how individual weaknesses may affect business operations * Support the planning and facilitation of cybersecurity tabletop, red-team, purple-team, and adversary simulation exercises * Contribute technical expertise to scenarios involving attacker behavior, detection, response, containment, recovery, and business disruption * Support cybersecurity framework and control reviews, including NIST CSF, CIS Controls, and similar standards * Assist with vendor security reviews, technical documentation reviews, and third-party risk activities * Develop clear findings that include supporting evidence, affected assets, risk, technical context, and practical remediation guidance * Prepare technical reports, project summaries, and executive-level updates for different audiences * Present findings and recommendations to technical teams, security leadership, and other stakeholders when needed * Work with system owners, administrators, vendors, and client contacts to clarify findings and support remediation planning * Maintain organized project notes, evidence, timelines, and engagement documentation * Support broader CISO/vCISO advisory and cybersecurity program activities as client needs evolve * Follow established testing boundaries, data-handling requirements, and escalation procedures ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Old tools, new tricks](https://www.wearedevelopers.com/videos/1916-old-tools-new-tricks) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [MCP doesn’t suck — your agent does](https://www.wearedevelopers.com/videos/100202-mcp-doesn-t-suck-your-agent-does) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Tips on mastering remote job interviews](https://www.wearedevelopers.com/magazine/23-tips-on-mastering-remote-job-interviews)